CVE-2021-22567 MEDIUM

CVE-2021-22567: Bidirectional Override in Dart SDK

Vendor Google Llc
Product Dart SDK
Weakness CWE-284
Published January 5, 2022
Last update April 21, 2025

CVSS base score

4.6/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L

What the vulnerability does

01Description

Bidirectional Unicode text can be interpreted and compiled differently than how it appears in editors which can be exploited to get nefarious code passed a code review by appearing benign. An attacker could embed a source that is invisible to a code reviewer that modifies the behavior of a program in unexpected ways.

Key dates

02Disclosure timeline

January 5, 2022 CVE published
April 21, 2025 Record updated